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QUESTION 21 

Scenario: A network engineer has created two selectors to use to populate a cache group in 
integrated caching. 

One selector, "Hit," will determine what to add to the group. The other, "Inval", will select what 
should be invalidated. 

Which command should the engineer run to create the cache group? 

A. add cache contentgroup CacheGroupl -hitParams Hit -invalParam Inval 

B. add cache contentgroup CacheGroupl -hitSelector Hit -invalSelector Inval 

C. set cache contentgroup CacheGroupl - hitParams Hit -invalParam Inval -type HTTP 

D. set cache contentgroup CacheGroupl -hitSelector Hit - invalSelector Inval -type HTTP 

Answer: B 
QUESTION 22 

Scenario: An organization has recently been penetration-tested by a security company. The 
findings have indicated that the NetScaler device is responding to requests revealing web server 
information within the HTTP response headers. 

Which NetScaler feature can a network engineer use to prevent this information from being leaked 
to a potential malicious user? 

A. Rewrite 

B. Responder 

C. Web Logging 

D. URL Transformation 

Answer: A 
QUESTION 23 

Scenario: Company Inc. wants to tag incoming requests with a header that indicates which browser 
is being used on the connection. This helps the server keep track of the browsers after the 
NetScaler has delivered the connections to the back end. 

The engineer should create actions to . (Choose the correct set of options 

to complete the sentence.) 

A. rewrite; insert tags on the client header 

B. responder; separate the client requests 

C. rewrite; insert tags on the server response 

D. responder; filter the browser type on the client header 

Answer: A 
QUESTION 24 

Which step could a network engineer take to prevent brute force logon attacks? 

A. Enable the Rate Limiting feature. 

B. Enable the AAA Application feature. 

C. Configure the Access Gateway policies. 

D. Configure the Cache redirection policies. 

Answer: A 
QUESTION 25 
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A network engineer should enable the Rate Limiting feature of a NetScaler system to mitigate the 
threat of attack. (Choose the correct option to complete the sentence.) 

A. reverse proxying 

B. Java decompilation 

C. source code disclosure 

D. brute force logon attacks 

Answer: D 
QUESTION 26 

Which NetScaler feature could be used to stall policy processing to retrieve information from an 
external server? 

A. Responder 

B. HTTPcallout 

C. AppExpert template 

D. EdgeSight monitoring 

Answer: B 
QUESTION 27 

An engineer has bound three monitors to a service group and configured each of the monitors with 
a weight of 10. 

How should the engineer ensure that the members of the service group are marked as DOWN 
when at least two monitors fail? 

A. Re-configure the weight of each monitor to 0. 

B. Configure the service group with a threshold of 21 . 

C. Configure the service group with a threshold of 20. 

D. Re-configure the weight of each monitor to 5, and configure the service group threshold to 15. 
Answer: C 

QUESTION 28 

A network engineer has noted that the primary node in an HA pair has been alternating as many 
as three times a day due to intermittent issues. 

What should the engineer configure to ensure that HA failures are alerted? 

A. LACP 

B. SNMP 

C. Route monitors 

D. Failover Interface Set 

Answer: B 
QUESTION 29 

The disk is full on a NetScaler appliance but NO alerts were generated by the SNMP traps. 
What is the likely cause of this failed alert? 

A. Auditing is not enabled. 

B. EdgeSight monitoring is not configured. 

C. The threshold was not set for the alarm. 
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D. Health monitoring has not been enabled. 
Answer: C 
QUESTION 30 

What type of protocol does AppFlow use for reporting? 

A. TCP 

B. UDP 

C. HTTP 

D. SSL_TCP 

Answer: B 
QUESTION 31 

Scenario: A network engineer monitoring an HTTP service-related issue needs to view only the 
relevant data pertaining to the service being monitored. The IP address of the back-end service 
being monitored is 10.10.1.99. The NSIP address is 10.10.1.230. 

Which command should the engineer execute to monitor data relevant to this issue only in realtime? 

A. telnet 

B. traceroute 

C. nsconmsg 

D. nstcpdump 

Answer: D 
QUESTION 32 

Scenario: A NetScaler environment uses two-factor authentication and the second authentication 
method is AD. A user logs in to the environment but does NOT receive access to the resources 
that the user should have access to. 

How can an engineer determine the AD authentication issue on the NetScaler? 

A. Check NSIogs. 

B. Use nsconmsg. 

C. Use the cat aaad. debug command. 

D. Check the authorization configuration. 

Answer: C 
QUESTION 33 

A NetScaler is configured with two-factor authentication. A user reported that authentication failed. 
How can an engineer determine which factor of the authentication method failed? 

A. Check NSIog. 

B. Use nsconmsg. 

C. Check the dashboard. 

D. Use cat aaad. debug command. 

Answer: D 
QUESTION 34 

Scenario: A NetScaler high availability (HA) pair has the following interfaces connected: 
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1/1 - Test network 

1/2 - Production network 

The network engineer needs to re-cable the test network and wants to ensure that, when the cable 
is removed, HA fail over does NOT occur unless the production network also goes down. 
Which step should the engineer take to meet these requirements? 

A. Configure LACP for interface 1/1 . 

B. Disable HA monitoring on interface 1/1. 

C. Set the throughput to 0 for interface 1/1 . 

D. Bind interfaces 1/1 and 1/2 into a channel, then disable HA monitoring. 
Answer: B 

QUESTION 35 

Scenario: A network engineer has modified the configuration of a content-switching virtual server, 
Websitejnain, because a second content-switching server that is capable of handling more 
connections has been added to the NetScaler implementation. Both servers will remain in operation. 
The engineer made the following configuration changes: 

>set cs vserver Website main -lbvserver New Server -backupVserver 
Old Server -redirectURL http://www.mydomain.com/maintenance -soMethod 
Connection -soThreshold 1000 
Why did the engineer enable the spillover option? 

A. To handle incoming connections in case the new server is unavailable 

B. To handle the extra connections using the old server without dropping them 

C. To redirect the extra connections to the Maintenance website when it is needed 

D. To handle incoming connections while the server reaches its limit of connections 

Answer: B 
QUESTION 36 

Scenario: A company is using Citrix NetScaler VPX for publishing internal resources using Citrix 
Access Gateway with Smart Access. Since the number of users has increased the company wants 
to migrate from Citrix NetScaler VPX to Citrix NetScaler MPX. The engineer is running a parallel 
installation of the Citrix NetScaler MPX and now needs to transfer the Citrix Access Gateway 
Universal Licenses from a Citrix NetScaler VPX to a Citrix NetScaler MPX platform. 
How should the engineer transfer the Citrix Access Gateway Universal License files from the VPX 
to the MPX? 

A. Backup the /nsconfig directory from the Citrix NetScaler VPX using SCP, restore the /nsconfig 
directory to the Citrix NetScaler MPX using SCP. 

B. Download the Access Gateway Universal License file(s) from the Citrix NetScaler VPX using SCP. 
Upload the Access Gateway Universal License file(s) to the Citrix NetScaler MPX using SCP. 

C. Logon to www.MyCitrix.com, return the Citrix Access Gateway Universal License file(s), reallocate 
the Citrix Access Gateway Universal License file using the hostname of the Citrix NetScaler MPX. 

D. Logon to www.MyCitrix.com, return the Citrix Access Gateway Universal License file(s), reallocate 
the Citrix Access Gateway Universal License file using the MAC Address of the Citrix NetScaler MPX. 

Answer: C 
QUESTION 37 

Scenario: A network engineer needs to add an NTP server to a NetScaler appliance. The NTP 
service is configured on 10.10.1.49. 

Which command should the network engineer use within the command-line interface to add in an 
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NTP server for time synchronization? 

A. add ntp server 10.10.1.49 

B. add server NTP 10.10.1.49 

C. add service NTP 10.10.1.49 TCP 123 

D. add service NTP 10.10.1.49 UDP 123 

Answer: A 
QUESTION 38 

A network engineer has enabled USIP and USNIP and set a unique IP address as the source IP 

using the proxyIP parameter on an INAT policy. 

Which is the correct order of precedence for the IP addresses? 

A. Unique IP-USIP-MIP-Error 

B. USIP-unique I P-USN I P-M IP-Error 

C. USIP-Unique I P-M I P-USN IP-Error 

D. USIP-USNIP-MIP-Unique IP-Error 

Answer: B 
QUESTION 39 

Scenario: An engineer configures two NetScaler appliances in a high availability (HA) pair. As part 
of a monthly health check, the engineer attempts to log on to the second node of the HA pair and 
is unable to access the management IP Address. The engineer logs on to the first NetScaler node 
and verifies that HA is working and operational. 
What does the engineer need to do to resolve this problem? 

A. Create an ACL to allow access to the NSIP of the second node. 

B. Add a SNIP for the Management IP Address of the second node. 

C. Ensure that HA Route Monitors have been configured for the second node. 

D. Change the NSRoot password back to default then log on to the second node. 

Answer: A 
QUESTION 40 

A public SSL certificate on a virtual server is about to expire and the NetScaler engineer needs to 
renew the certificate before it expires. 

Which step must the engineer take to renew the SSL Certificate? 

A. Generate a new CSR 

B. Recreate the Private Keys 

C. Execute CRL Management 

D. Update the existing certificate 

Answer: D 
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